CVE-2026-78187
Piwigo Public Authentication cross site scripting
CVSS Score
3.1
EPSS Score
0.0%
EPSS Percentile
0th
A vulnerability has been found in Piwigo 16.3.0. This impacts an unknown function of the component Public Authentication Page. Such manipulation of the argument lang leads to cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. Upgrading to version 16.4.0 will fix this issue. The name of the patch is 5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e. It is recommended to upgrade the affected component.
| CWE | CWE-79 CWE-94 |
| Vendor | n/a |
| Product | piwigo |
| Published | Aug 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for n/a piwigo
Be the first to know when new low vulnerabilities affecting n/a piwigo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
n/a / Piwigo
16.3.0
References
vuldb.com: https://vuldb.com/vuln/394569 vuldb.com: https://vuldb.com/vuln/394569/cti vuldb.com: https://vuldb.com/cve/CVE-2026-78187 vuldb.com: https://vuldb.com/submit/885228 github.com: https://github.com/Piwigo/Piwigo/security/advisories/GHSA-rr39-mf4j-6594 github.com: https://github.com/Leousum/VulnPoC/blob/main/Piwigo%2016.3.0/reflected_XSS.md github.com: https://github.com/Piwigo/Piwigo/commit/5277a7dee4b8f1a174f1d69e1e2a4e1c82a3fc9e github.com: https://github.com/Piwigo/Piwigo/releases/tag/16.4.0 github.com: https://github.com/Piwigo/Piwigo/
Credits
๐ Leousum (VulDB User)